TsunamiSight
A client that extracts vulnerability-related observations from the Tsunami Security Scanner plugins repository and publishes them as sightings on a Vulnerability-Lookup instance.
Each committed Tsunami detector is a compiled, executable proof-of-concept for
a specific vulnerability. Google's newer templated plugins (.textproto
files under templated/templateddetector/plugins/) are also parsed for CVE
sightings. TsunamiSight emits one sighting per (plugin, CVE) pair with the
default type published-proof-of-concept.
Installation
$ pipx install TsunamiSight
$ export TSUNAMISIGHT_CONFIG=~/.TsunamiSight/conf.py
$ git clone https://github.com/google/tsunami-security-scanner-plugins.git tsunami-security-scanner-plugins
Copy tsunamisight/conf_sample.py to your chosen config path and fill in the
token + URL.
With Docker
git clone <this repo>
cd TsunamiSight
cp tsunamisight/conf_sample.py tsunamisight/conf.py # then fill in token
docker compose up --build
Usage
TsunamiSight --help
usage: TsunamiSight [-h] [--init] [--dry-run]
Extract CVE references from the Tsunami plugins repo and publish sightings.
options:
-h, --help show this help message and exit
--init Full sweep: emit sightings for every CVE-bearing plugin.
--dry-run Parse and print (plugin, CVE, timestamp) triples without POSTing.
License
TsunamiSight is licensed under GNU General Public License version 3
Copyright (c) 2026 Computer Incident Response Center Luxembourg (CIRCL)
Copyright (C) 2026 Philippe Parage - https://github.com/pparage
Release files for TsunamiSight 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| tsunamisight-0.1.1.tar.gz | 18.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| tsunamisight-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 39.7 kB
Release files / tsunamisight-0.1.1.tar.gz
| Download URL | tsunamisight-0.1.1.tar.gz |
|---|---|
| Size | 18.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0999a9aaaf89a55c6900b8d7bad5306689b464abd84c413d7e626058097f7c5a
|
|
BLAKE2b-256 checksum How to use checksums |
218ee6b4b8b1aaa7b5cde49146cdc8687e40d5044541fc2688cb61ff8cafb055
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 29, 2026.
Transparency logRelease files / tsunamisight-0.1.1-py3-none-any.whl
| Download URL | tsunamisight-0.1.1-py3-none-any.whl |
|---|---|
| Size | 21.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9a549154aeb553c2867fbb76e1f345bce7964d3853e98b201e194b416b1e6bad
|
|
BLAKE2b-256 checksum How to use checksums |
0dd0809e09a28c7ae2df38fc05f352d45abda40546b476400a8014643e340d96
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 29, 2026.
Transparency log